CVE-2006-3649
EXPLOITEDMicrosoft Visual Basic for Applications SDK 6.0-6.4 - Buffer Overflow via Document Properties
Title source: llmExploitation Summary
CVE-2006-3649 has been observed exploited in the wild (reported by VulnCheck KEV).
Description
Buffer overflow in Microsoft Visual Basic for Applications (VBA) SDK 6.0 through 6.4, as used by Microsoft Office 2000 SP3, Office XP SP3, Project 2000 SR1, Project 2002 SP1, Access 2000 Runtime SP3, Visio 2002 SP2, and Works Suite 2004 through 2006, allows user-assisted attackers to execute arbitrary code via unspecified document properties that are not verified when VBA is invoked to open documents.
References (8)
Core 8
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-047
Patch, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/159484
Third Party Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/21408
Patch, US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-220A.html
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3214
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/19414
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A694
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1016656
Scores
EPSS
0.1017
EPSS Percentile
95.2%
Details
VulnCheck KEV
2006-08-08
Status
published
Products (3)
microsoft/visual_basic
6.2 (2 CPE variants)
microsoft/visual_basic
6.3
microsoft/visual_basic
6.4
Published
Aug 09, 2006
Tracked Since
Feb 18, 2026